Re: Email Web of Trust - Problem Statement

"Peter J. Holzer" <[email protected]> Tue, 9 Mar 2004 12:18:00 +0100
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
On 2004-03-08 20:36:20 -0500, Yakov Shafranovich wrote:
> Peter J. Holzer wrote:
> >On 2004-03-08 17:21:34 -0500, Yakov Shafranovich wrote:
> ...
> >>>More generally, the trust could be based on a particular policy or set
> >>>of policies:  A particular domain, for example, might be trusted to
> >>>adhere to certain antispam policies regarding UBE, authenticating
> >>>senders, responding to complaints, etc.
> >>>
> >>>I think we need to resolve this question before discussing mechanisms.
> >>
> >>I was actually thinking of whether a specific domain is trusted to
> >>provide non-forged data in SMTP, staying away from the definitions of
> >>spam.
> >
> >
> >How do you determine that? It is relatively simple to get an opinion
> >(either from a user or a program like SpamAssassin) on whether a given
> >message is spam or not. But whether the return-path is forged or not is
> >an objective criterium which can not easily be verified. If you get a
> >message from <[email protected]> from the MTA 143.130.50.112, is that
> >forged or not?
> >
>
> Isn't the whole point of a trust system is to provide a way to verify
> something via a vouching mechanism rather than relying on a test by
> SpamAssasin or a user?

Yes, but somebody has to vouch, or else there are no vouchers to rely
on.

I feel comfortable in vouching that I have never received spam from a
given MTA. I can do that manually by checking through my mail logs
(which would be rather tedious). This can also be easily partially or
fully automated.

I do not feel comfortable vouching that a domain/MTA/organization
doesn't send forged mails without knowing if and how they verify the
sender. In general, I don't have that information, so I can't vouch for
them. (In fact, it isn't even clear what a "forged mail" is - if I send
a mail with a sender of <[email protected]> from the office instead of from
home, is that forged? Some would say yes - I should only send as
<[email protected]> through my employers MTA and only as <[email protected]>
through my private MTA; but both addresses belong to me, so I wasn't
lying about the sender, and the path a mail takes doesn't change the
fact whether the mail itself is forged or not.)

	hp

--
   _  | Peter J. Holzer    | I think we need two definitions:
|_|_) | Sysadmin WSR       | 1) The problem the *users* want us to solve
| |   | [email protected]         | 2) The problem our solution addresses.
__/   | http://www.hjp.at/ |    -- Phillip Hallam-Baker on spam

[demime 0.99d.1 removed an attachment of type application/pgp-signature]